Resources · Claude connector

Claude Black Duck Security Scanner connectorWhat Claude can do in your Black Duck Security Scanner account.

The Claude Black Duck Security Scanner connector exposes 2 tools. Both read your code to look for vulnerabilities, 0 write anything, and 0 remain undocumented. Below: what Claude can scan on your machine, where the code goes, and what you need before it works.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What changes when Claude can run Black Duck scans

Instead of switching to a separate security tool after every round of edits, a developer asks Claude to check the work in plain words. Claude runs a Black Duck Signal scan on the project, reads the findings by severity and explains them in the conversation, so the fix can start while the code is still fresh in mind.

Check only what you just changed. With run_changes_security_scan, Claude scans the edits in a git project, either the work not yet committed or everything since a reference branch such as main, and returns counts by severity.

Audit a folder that matters. run_security_scan targets specific files or directories, which Black Duck recommends for projects without git or for a focused review of a sensitive path.

Turn a report into next steps. Both tools hand back a SARIF report and analysis guidance, which Claude can walk through finding by finding, one severity level at a time, in the same conversation.

What it will not do: the tools scan and report; no source says they modify your files. Nothing scans by itself on each commit either, since Claude acts only while it answers. And the scanned code leaves your machine for Black Duck's analysis service. For other families on this site, see the Integrations hub.

Vocabulary

Five words to get straight

The Claude terms this page relies on, each explained once.

Connector
A link set up once between Claude and an outside service or program, so Claude can use it while it answers you.
Tool
One named action a connector makes available. Claude decides when to call it, and the directory sheet lists every tool by its name.
Authorization
The service's own screen where you grant Claude the access it will use afterwards. It is granted per person and can be taken back.
Approval
The confirmation Claude waits for before doing something that changes an account, shown in the chat at the point it matters.
MCP
The shared standard connectors are built on: it lets an assistant like Claude work with an outside service such as Black Duck.
Connect

Set up the Claude Black Duck Security Scanner connector

  1. 01

    Find Black Duck in the list

    Open Claude's settings, go to Customize, then Connectors, and locate Black Duck Security Scanner. On a Team or Enterprise workspace, an Owner or Primary Owner enables it for the organization before members can use it individually.

  2. 02

    Start the connection

    Click Connect on its row and finish what the window asks. If the link fails later, choose Disconnect and connect again, which is how Claude expects a broken connection to be repaired.

  3. 03

    Read what you approve

    Where an authorization screen appears, read it before accepting: it is written by the service, not by Claude, and it sets the scope of access Claude will use from then on.

Tools

The 2 scanning tools

Black Duck Security Scanner gives Claude 2 tools: 2 that read your account, 0 that change something in it.

Both tools are described in Black Duck's own documentation. Names stay as Claude displays them, in English.

  • 2 read

What Claude reads (2)

2 tools

Two tools that analyze your code and report findings without editing it.

run_changes_security_scan

Runs a fast, incremental scan limited to the code you touched in a git project: staged and unstaged work, or the difference since a reference branch. You get a SARIF report and issue counts by severity.

When it helps
before opening a pull request, you ask whether your branch introduced a new flaw compared with main.
Watch out
the project must use git, since that is how the tool knows what changed.

Sourcegithub.com · October 1, 2026 ↗

run_security_scan

Analyzes the specific files or directories you point to, inside a given project path, and returns the same kind of report with findings sorted by severity.

When it helps
a team without git wants the payment module checked on its own, folder by folder.
Watch out
by default a scan stops after 30 minutes, a delay Black Duck lets you adjust.

Sourcegithub.com · October 1, 2026 ↗

Approvals

What Claude asks before acting

By default, Claude pauses and asks for confirmation before each action it carries out on an account for someone, inside the conversation.

No source says whether Claude asks before starting a Black Duck scan, so that default rule is what applies. On Team and Enterprise workspaces, owners decide whether members may let some actions pass without a prompt every time, and they can restrict what a connector may do for the whole organization; nobody overrides that from their own account. Claude also works with the rights of the person who set it up and nothing more.

Plans

Which plans it runs on

No official source publishes plan availability connector by connector: 0 of the 819 directory sheets shows it, and the gap is real.

The published rule is general. Remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions like this one install on Claude Desktop. On Team and Enterprise, an Owner or Primary Owner opens a connector for the organization before members connect. The connector's sheet in the official directory shows its current state. Only Black Duck documents this connector; no Claude help page covers it.

Limits

Where the Black Duck connector stops

A connector is not an automation. Claude calls these scans while it answers you, so nothing runs on its own when you commit or push.

By default, its sheet exposes only reading, an observed floor rather than a promise: an administrator can open actions that no public sheet shows. The partner badge is not a security audit, and Anthropic writes on every sheet that it neither chooses the tools a publisher exposes nor guarantees how they behave. Install what comes from a publisher you trust. To compare with a connector that works on a remote business account, see the Claude agility-cms connector.

Need help

Need help connecting Black Duck Security Scanner to Claude?

A person reads every message.

FAQ

Questions about the Claude Black Duck Security Scanner connector

01What can Claude do with the Black Duck Security Scanner connector?
Claude can run Black Duck Signal security scans on code from your machine and explain the results. One tool scans only what changed in a git project, either uncommitted edits or everything since a reference branch. The other scans files or folders you name, including in projects that do not use git. Both return a SARIF report with issue counts by severity, which Claude then reads with you. By default, a scan stops after 30 minutes.
02Can Claude change my code or push fixes with this connector?
No documented tool edits files or pushes anything. Black Duck describes both tools as scans that return a report, issue counts and analysis guidance. By default the sheet exposes only reading, which is an observed floor, not a guarantee. If Claude suggests a fix, applying it is a separate step that does not go through these two tools, and you decide whether it happens. Treat these tools as a diagnosis, not a repair.
03Does Claude ask before starting a scan?
By default, Claude asks for confirmation before each action it takes on an account for someone. No source describes a specific prompt for either Black Duck scan, so that general rule is what covers them. In an organization workspace, owners decide whether members may let certain actions pass without asking each time, and they can restrict what the connector may do for everybody at once. Since the scans only read code, the main thing to weigh is where that code goes.
04Which Claude plans support the Black Duck connector?
No official source publishes plan availability for a given connector, and none of the 819 directory sheets shows it. The general rule says desktop extensions install on Claude Desktop, remote connectors are open to all users across Claude's apps, and on Team and Enterprise an Owner or Primary Owner enables a connector first. Check the connector's directory sheet for its state on your account: it is the only place that shows its current status.
05Does my source code leave my computer during a scan?
Yes. According to the directory sheet, the code being scanned is sent to Black Duck's remote service, which does the analysis. The extension runs locally, but the analysis itself happens on Black Duck's side, which is why your firewall has to let it reach two Black Duck addresses over HTTPS. If part of your code must never leave the building, keep it out of the scanned paths. That transfer is described by the directory sheet itself, not just by Black Duck.
06Why does the change scan not work on my project?
Most likely the project is not a git repository. Black Duck says the change-based scan relies on git to find which files changed, whether you compare uncommitted edits or a branch against main. Without git, the file-and-folder scan is the documented alternative. A missing license or key, or a blocked firewall, can also stop any scan before it starts. Check those three points first when nothing happens; the firewall must reach repo.blackduck.com and llm.core.blackduck.com.
07Claude or an automation tool for Black Duck scans?
They serve different uses, so the choice follows the task rather than a ranking. Claude suits an interactive check: you ask for a scan while coding and discuss each finding on the spot. A pipeline that must scan every commit without anyone asking is a different job, and this connector has no trigger of its own; Claude only scans while it is answering you. For a quick check during the day, the conversation is the faster route.